
Analyse complète et preuve de concept pour CVE-2025-6218 - vulnérabilité de type Path Traversal et RCE dans WinRAR affectant les versions 7.11 et antérieures
⚠️ VULNÉRABILITÉ CRITIQUE - Exploitation active confirmée
CVE-2025-6218 est une vulnérabilité critique de path traversal dans WinRAR qui permet l'exécution de code arbitraire. Actuellement exploitée par des groupes APT comme GOFFEE, Bitter (APT-C-08) et Gamaredon.
CVE-2025-6218 est une vulnérabilité CRITIQUE de path traversal dans WinRAR pour Windows qui permet aux attaquants d'exécuter du code arbitraire.
| Aspect | Détail |
|---|---|
| Score CVSS | 7.8 (Élevé) |
| Versions vulnérables | WinRAR ≤ 7.11 (Windows uniquement) |
| Plateformes | Windows 10, 11, Server |
| Utilisateurs concernés | ~500 millions |
| Corrigé dans | WinRAR 7.12 (Juin 2025) |
| Statut | 🔴 Exploitation ACTIVE |
| CISA KEV | Ajouté le 9 décembre 2025 |
Un attaquant peut :
WinRAR ne valide pas correctement les chemins des fichiers à l'intérieur d'archives .rar spécialisées. Lorsqu'un utilisateur extrait une archive malformée, les fichiers peuvent être écrits dans des chemins arbitraires en dehors du dossier d'extraction prévu en utilisant des séquences de path traversal (../ ou ..\\).
// Pseudocodice - WinRAR v7.11 (VULNERABILE) void extract_file(rar_entry *entry, char *dest_dir) { char final_path[MAX_PATH];
strcpy(final_path, dest_dir); // "C:\\Temp\\"
strcat(final_path, entry->filename); // + "..\\..\\..\\Windows\\System32\\malware.exe"
// ❌ ERRORE: Nessuna validazione del path traversal!
// final_path = "C:\\Temp\\..\\..\\..\\Windows\\System32\\malware.exe"
// Risolto come: "C:\\Windows\\System32\\malware.exe" ← EXPLOIT!
create_file(final_path); // File creato in directory non intesa
}
### Protections absentes dans v7.11
- ❌ Aucun contrôle si le fichier reste dans `dest_dir`
- ❌ Aucun filtre sur les séquences `..` ou `.`
- ❌ Aucune normalisation des chemins
- ❌ Aucune liste blanche de répertoires autorisés
- ❌ Aucune validation de confinement
### Le correctif dans v7.12```c
// WinRAR v7.12 (PATCHED)
bool is_path_contained(char *path, char *base_dir) {
char canonical[MAX_PATH], canonical_base[MAX_PATH];
// Normalizza entrambi i percorsi
GetFullPathName(path, MAX_PATH, canonical, NULL);
GetFullPathName(base_dir, MAX_PATH, canonical_base, NULL);
// Verifica contenimento
if (strncmp(canonical, canonical_base, strlen(canonical_base)) != 0) {
return false; // Path esce dalla directory base
}
return true;
}
void extract_file_safe(rar_entry *entry, char *dest_dir) {
char final_path[MAX_PATH];
strcpy(final_path, dest_dir);
strcat(final_path, entry->filename);
// ✅ FIX: Verifica che il file rimane dentro dest_dir
if (!is_path_contained(final_path, dest_dir)) {
skip_extraction(); // Rifiuta estrazione
log_error("Path traversal detected!");
return;
}
create_file(final_path); // Adesso sicuro
}
Cartella di Estrazione: C:\Temp\Extract
Path nel RAR (craft): ..\..\..\..\Users\\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\payload.bat
Risoluzione Path: C:\Temp\Extract\.. = C:\Temp\ C:\Temp\.. = C:\ C:\.. = C:\ (non può andare oltre)
= C:\Users\\AppData\Roaming\...\Startup\payload.bat ✓
### Schéma du flux d'attaque```
┌─────────────────────────────────────────────┐
│ 1. Attaccante crea RAR con path craft │
│ es: ..\\..\\..\\Startup\\malware.bat │
└─────────────────────────────────────────────┘
↓
┌─────────────────────────────────────────────┐
│ 2. Distribuzione via spear-phishing │
│ Email mirata con allegato RAR │
└─────────────────────────────────────────────┘
↓
┌─────────────────────────────────────────────┐
│ 3. Vittima estrae archivio con WinRAR │
│ (versione ≤ 7.11) │
└─────────────────────────────────────────────┘
↓
┌─────────────────────────────────────────────┐
│ 4. WinRAR non valida path traversal │
│ File estratto in Startup folder │
└─────────────────────────────────────────────┘
↓
┌─────────────────────────────────────────────┐
│ 5. Al boot: payload eseguito │
│ RAT stabilisce C2 connection │
└─────────────────────────────────────────────┘
| Version | État | Notes |
|---|---|---|
| ≤ 7.10 | 🔴 VULNÉRABLE | Tous les exploits fonctionnent |
| 7.11 | 🔴 VULNÉRABLE | Dernière version vulnérable |
| 7.12 Beta 1+ | 🟢 PATCHED | Fix path traversal |
| 7.12+ | 🟢 PATCHED | Version stable avec correctif |
| UNIX / Android | ✅ NOT AFFECTED | Versions non-Windows non concernées |
(Get-Item "C:\Program Files\WinRAR\WinRAR.exe").VersionInfo.FileVersion
wmic datafile where name="C:\\Program Files\\WinRAR\\WinRAR.exe" get Version
---
## 🌍 Scénarios d'Attaque
### Scénario 1 : Bitter/APT-C-08 Spear-Phishing (CONFIRMÉ ACTIF)
**Objectif** : Gouvernement, organisations militaires, institutions stratégiques```
Email Phishing:
From: [email protected]
Subject: "Provision of Information for Sectoral for AJK.rar"
Attachment: Provision_of_Information.rar
Contenuto Archive:
├── Document.docx (esca legittima - report convincente)
└── ..\\..\\..\\..\\Users\\User\\AppData\\Roaming\\Microsoft\\Office\\STARTUP\\Template.dotm
(macro malato nascosto)
Esecuzione:
1. Vittima estrae RAR
2. WinRAR non valida path → Template.dotm finisce in Office STARTUP
3. Prossimo avvio Word → Macro eseguita automaticamente
4. PowerShell downloader attivato
5. C# Trojan scaricato: WmRAT, MiyaRAT, ZxxZ
6. C2 Server: johnfashionaccess.com
7. Capabilities:
- Keylogging
- Screenshot capture
- RDP credential stealing
- File exfiltration
- Lateral movement